Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.8 CVE-2026-50021

pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field_CVE-2026-50021

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is a...

pnpm pnpm < 10.34.0 CVE
MEDIUM 6.9 CVE-2026-50017

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry_CVE-2026-50017

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a ...

pnpm pnpm < 10.33.4 CVE
MEDIUM 6.4 CVE-2026-50014

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit_CVE-2026-50014

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- s...

pnpm pnpm < 10.33.4 CVE
MEDIUM 4.8 CVE-2026-48995

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile_CVE-2026-48995

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will in...

pnpm pnpm < 10.33.4 CVE
MEDIUM 6.8 CVE-2026-47770

jq: stack overflow in deep structural equality_CVE-2026-47770

jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on j...

jqlang jq < 1.8.2 CVE
MEDIUM 4.8 CVE-2026-56788

RTKLIB 2.4.3 – Out-of-bounds Read via Negative Array Index in getcodepri_CVE-2026-56788

RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allo...

tomojitakasu RTKLIB CVE
MEDIUM 6.9 CVE-2026-56787

RTKLIB 2.4.3 – Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message_CVE-2026-56787

RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:1446 that allows remote att...

tomojitakasu RTKLIB CVE
MEDIUM 5.3 CVE-2026-56779

MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters_CVE-2026-56779

MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to m...

1Panel-dev MaxKB CVE
MEDIUM 5.3 CVE-2026-56774

Kanboard – Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID_CVE-2026-56774

Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to...

kanboard kanboard CVE
MEDIUM 5.3 CVE-2026-56772

NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions Endpoint_CVE-2026-56772

NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplyi...

samuelclay NewsBlur CVE